A global online retailer moved its quarterly user access reviews to a BalkanID managed IGA service and completed its next internal audit with zero deficiencies, a first for the company.
Systems
Okta (including Okta Identity Governance), Google Workspace, Active Directory (via on-prem agent), finance, tax, endpoint, warehouse and data platforms
Drivers
Internal Audit sign-off on quarterly reviews; reducing dependence on a single identity vendor
Challenges before BalkanID
- Reviews ran partly in the identity provider's governance module and partly in CSV and Excel lists for every app outside it.
- The security team spent an estimated 500 hours a year preparing, chasing and evidencing reviews.
- Many accounts in finance and operational systems did not map to a directory identity, so they were never reviewed consistently.
- Internal Audit needed data validation it could tie out, not screenshots.
What BalkanID delivers as a managed service
- BalkanID builds and maintains the extractors, then creates, runs and closes campaigns every quarter. The customer's control owners only make review decisions.
- A hybrid model: accounts that map to the identity provider are reviewed there, and unmapped accounts are reviewed in BalkanID, so nothing falls through.
- Playbooks for deprovisioning, Jira tickets for disconnected apps, chat reminders, failure alerts, and automatic reassignment to the control owner seven days before close.
- Audit packages with data-validation tie-outs in the format Internal Audit agreed.
- Rollout: Over two dozen apps, including cloud, data and developer platforms.
Outcomes
- Quarterly UAR audit completed with zero deficiencies for the first time.
- Internal Audit accepted BalkanID's validation format and evidence structure.
- Review preparation, chasing and evidence moved off the internal team.
- New findings rules added after the audit surfaced deprovisioned users still active in apps, now caught continuously.